2025 CVE Vulnerabilities

45,296 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-2073HIGH8.8Out-of-Bounds Read in netfilter/ipset in Linux Kernel ChromeOS [6.1, 5.15, 5.10, 5.4, 4.19] allows a local attacker with...
CVE-2025-24911MEDIUM4.9Overview   XML documents optionally contain a Document Type Definition (DTD), which, among other features, enable...
CVE-2025-24910MEDIUM4.9Overview   XML documents optionally contain a Document Type Definition (DTD), which, among other features, enable...
CVE-2025-24909MEDIUM4.4Overview   The software does not neutralize or incorrectly neutralize user-controllable input before it is placed...
CVE-2025-24908MEDIUM6.8Overview   The product uses external input to construct a pathname that should be within a restricted directory, ...
CVE-2025-24907MEDIUM6.8Overview   The product uses external input to construct a pathname that should be within a restricted directory, ...
CVE-2025-1704MEDIUM6.5ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 15823.23.0 on Chromebooks allows enrolled users...
CVE-2025-1568HIGH8.8Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 16063.87.0 allows an attacker...
CVE-2025-1566HIGH7.5DNS Leak in Native System VPN in Google ChromeOS Dev Channel on ChromeOS 16002.23.0 allows network observers to expose p...
CVE-2025-0758MEDIUM6.1Overview  The product specifies permissions for a security-critical resource in a way that allows that resource to be...
CVE-2025-0757MEDIUM4.4Overview   The software does not neutralize or incorrectly neutralize user-controllable input before it is placed ...
CVE-2025-0756CRITICAL9.1Overview   The product receives input from an upstream component, but it does not restrict or incorrectly restric...
CVE-2025-43703MEDIUM5.4An issue was discovered in Ankitects Anki through 25.02. A crafted shared deck can result in attacker-controlled access ...
CVE-2025-32791MEDIUM4.3The Backstage Scaffolder plugin houses types and utilities for building scaffolder-related modules. A vulnerability in t...
CVE-2025-32789LOW3.7EspoCRM is an Open Source Customer Relationship Management software. Prior to version 9.0.7, users can be sorted by thei...
CVE-2025-32787LOW3.1SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. Versions 5.02.5184 to 5.02.5187 are vulnerab...
CVE-2025-32783MEDIUM4.3XWiki Platform is a generic wiki platform. A vulnerability in versions from 5.0 to 16.7.1 affects users with Message Str...
CVE-2025-32433CRITICAL10Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and O...
CVE-2025-31478HIGH8.2Zulip is an open-source team collaboration tool. Zulip supports a configuration where account creation is limited solely...
CVE-2025-25230HIGH7.8Omnissa Horizon Client for Windows contains an LPE Vulnerability. A malicious actor with local access where Horizon Clie...
CVE-2025-3730MEDIUM5.5A vulnerability, which was classified as problematic, was found in PyTorch 2.6.0. Affected is the function torch.nn.func...
CVE-2025-3729CRITICAL9.8A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Managemen...
CVE-2025-3728HIGH7.8A vulnerability classified as critical was found in SourceCodester Simple Hotel Booking System 1.0. This vulnerability a...
CVE-2025-3727CRITICAL9.8A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. This affects an unknown part of the com...
CVE-2025-3620HIGH8.8Use after free in USB in Google Chrome prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corr...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now